Particle.news

Attackers Actively Exploit Critical Zimbra Remote‑Code Flaw

Unauthenticated SMTP requests can run operating‑system commands as the zimbra user, threatening email theft or full server takeover unless the July 20 patch is applied.

Overview

  • Poland’s CERT Polska confirmed active exploitation of CVE‑2026‑73570 in mid‑August and urged administrators to hunt for signs of compromise.
  • The bug is a command‑injection flaw in Zimbra’s SNMP notification code that lets an unauthenticated attacker send a crafted SMTP request to execute OS commands as the zimbra user.
  • Zimbra released a fix in version 10.1.20 on July 20, but internet scans by Shadowserver find roughly 12,100 Zimbra servers reachable online, many of which may still be vulnerable or unpatched.
  • CERT Polska published indicators of compromise and tells admins to check /var/log/zimbra.log for unexpected service restarts and recent files owned by zimbra in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/.
  • Because past Zimbra bugs have been used by state‑linked and criminal groups to steal mail and credentials, organizations should prioritize patching, limit SMTP exposure, monitor egress traffic, and assume risk until investigations confirm no breach.